What Is SOX (Sarbanes-Oxley Act)?

Also called: Sarbanes-Oxley, Sarbox, Public Company Accounting Reform and Investor Protection Act

Related problems: Preparing for an IPO and told our IT controls need to be audit-ready; Auditors asking for evidence of user access reviews and change approvals; Need SOC 1 reports from the vendors that run our financial systems; Not sure which SOX requirements apply to a smaller public company

The Sarbanes-Oxley Act (SOX) is a US federal law passed in 2002 after a series of major accounting scandals. It requires public companies to maintain internal control over financial reporting, has executives personally certify their financial reports, and, for larger companies, requires an outside auditor to attest to those controls. It also created the Public Company Accounting Oversight Board (PCAOB) to oversee auditors of public companies. This entry is an overview for buyers, not legal or accounting advice.

At a glance

  • SOX applies mainly to companies with securities registered with the US Securities and Exchange Commission (SEC), including many foreign companies listed in the US.
  • Section 302 makes the CEO and CFO certify each periodic report and their responsibility for controls.
  • Section 404 requires an annual management assessment of internal control over financial reporting; larger filers also need an auditor’s attestation.
  • IT general controls, such as access, change management and operations for financial systems, are a core part of the audit.
  • Vendors that run financially significant systems usually provide SOC 1 reports so their controls can be relied on.

What problem it solves

Investors depend on financial statements being accurate. The scandals that led to SOX showed that executives could sign off on numbers without being accountable, and that weak internal controls let errors and fraud go undetected. SOX makes leaders personally responsible for the reports, forces companies to document and test their controls, and puts auditors under independent oversight.

For IT, the effect is concrete. The systems that produce financial numbers, such as ERP, billing, payroll, databases and the infrastructure under them, need controls over who has access, how changes are approved and tested, and how jobs and backups run. Management tests those controls each year, and at larger companies the external auditor does too.

How it works

Scoping. The company identifies significant accounts, the business processes behind them and the IT systems those processes rely on.

Controls. For each process, the company documents key controls. On the IT side these are IT general controls: user provisioning and access reviews, privileged access, change management, segregation of duties, job scheduling, backup and incident handling.

Testing and remediation. Management tests the controls during the year, often with internal audit or outside advisors, and fixes deficiencies before year end.

Assessment and certification. Management states its conclusion on the effectiveness of controls in the annual report, and executives certify each quarterly and annual report. For larger filers, the external auditor issues its own opinion on internal control.

Service organizations. Where a vendor performs part of a control, the auditor typically relies on a SOC 1 report on that vendor, and the company must operate the complementary user entity controls the report lists.

Filer categories

SOX has no certification levels, but its heaviest requirement depends on the company’s SEC filer category, which is based on public float and, for smaller companies, revenue.

Category Who it covers Section 404 requirement What it typically shows
Large accelerated filer Largest public companies by public float Management assessment plus external auditor attestation (404(b)) Annual report with management’s report and the auditor’s opinion on internal control
Accelerated filer Mid-sized public companies, excluding certain low-revenue smaller reporting companies Management assessment plus external auditor attestation Same as above
Non-accelerated filer Smaller public companies, including many low-revenue smaller reporting companies Management assessment only (404(a)) Management’s report; no auditor attestation on internal control
Emerging growth company Newly public companies that qualify, for a limited period Management assessment; auditor attestation not required during the exemption Management’s report

Thresholds are set in SEC rules; confirm your status with your auditor and counsel.

When it matters for buyers

  • When preparing for an IPO. IT controls need to be designed, documented and operating before the first audit.
  • When choosing ERP, payroll, cloud or data center providers. Ask for a SOC 1 report scoped to the service.
  • When moving financial systems to the cloud. Access and change controls need to be rebuilt for the new environment.
  • When an acquisition brings in another company’s systems. They usually have to meet the acquirer’s control standards.

Our governance, risk and compliance overview covers advisors and tools for control testing, and our privileged access management overview covers one of the controls auditors look at most closely.

Questions to ask vendors

  • Do you provide a SOC 1 Type II report, and does it cover the specific service and locations we’d use?
  • What period does it cover, and will you provide bridge letters for the gap to our year end?
  • Which complementary user entity controls does the report expect us to operate?
  • How do you control and log privileged access to systems holding our financial data?
  • How are changes to the service approved, tested and communicated to us?
  • Can we export the access and change logs our auditors will ask for?

How it differs from SOC 2

SOC 2 is an attestation report on a service organization’s controls for security and related criteria, requested by customers. SOX is a law that applies to public companies. The report that supports SOX reliance on a vendor is usually SOC 1, which focuses on controls relevant to customers’ financial reporting, not SOC 2. Many providers offer both. SOX’s access controls overlap with identity and access management (IAM), and financial institutions often face SOX alongside the Gramm-Leach-Bliley Act (GLBA). A governance, risk and compliance (GRC) program usually maps SOX controls together with other data security compliance requirements.

Frequently Asked Questions

Does SOX apply to private companies?
Mostly no. Its main control and certification requirements apply to companies with securities registered with the SEC. Private companies feel it when they prepare for an IPO, are acquired by a public company, or serve public companies as vendors whose controls affect financial reporting. A few provisions, such as those on document destruction, are broader; check with counsel.
What is the difference between SOX 302 and SOX 404?
Section 302 requires the CEO and CFO to certify each periodic report, including that they are responsible for internal controls. Section 404 requires management to assess internal control over financial reporting each year, and for larger filers, an external auditor to attest to that assessment.
Do all public companies need an auditor's 404(b) attestation?
No. The auditor attestation applies to accelerated and large accelerated filers. Non-accelerated filers, including many smaller reporting companies with low revenue, and emerging growth companies during their exemption period are not required to obtain it, though management must still assess controls. Confirm your filer status with your auditor and counsel.
How does SOX affect our IT vendors?
If a vendor runs systems that affect financial reporting, such as an ERP, payroll or data center service, your auditor will want assurance about its controls. That usually comes from a SOC 1 report covering the relevant service, plus the complementary controls the report says you must operate yourself.
Is SOX a cybersecurity law?
Not directly. It is about reliable financial reporting. IT general controls such as access management, change management and operations are in scope because they protect financial data and systems, but broader cybersecurity disclosure is covered by separate SEC rules.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.